Commit Graph

390 Commits

Author SHA1 Message Date
Florence Blanc-Renaud
398f0e1724 ipa-4.12.2-15
- Resolves: RHEL-67912 Add DNS over TLS Support
2025-02-12 19:59:14 +01:00
Florence Blanc-Renaud
73e3a943d0 ipa-4.12.2-14
- Resolves: RHEL-78766 Include latest fixes in python3-ipatests package
- Resolves: RHEL-77965 ipa-server-install failing on slow hsm

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2025-02-11 18:09:01 +01:00
Thomas Woerner
837c02b504 ipa-4.12.2-13
- Resolves: RHEL-67912 Add DNS over TLS Support, require bind 32:9.18.33-2 and bind-dyndb-ldap 11.11-1

Signed-off-by: Thomas Woerner <twoerner@redhat.com>
2025-02-11 17:45:23 +01:00
Florence Blanc-Renaud
5a34f265f7 ipa-4.12.2-12
- Resolves: RHEL-72580 A slow HSM can cause IPA server installation to fail setting up certificate tracking

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2025-01-28 14:12:51 +01:00
Florence Blanc-Renaud
d45f8dce3d ipa-4.12.2-11
- Resolves: RHEL-75658 Include latest fixes in python3-ipatests package
- Resolves: RHEL-74466 kinit with external idp user is failing

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2025-01-22 09:47:45 +01:00
Florence Blanc-Renaud
84d0312b89 ipa-4.12.2-10
- Resolves: RHEL-72580
A slow HSM can cause IPA server installation to fail setting up certificate tracking
- Resolves: RHEL-71964
KRA installation failure caused by a certificate mismatch in NSS DB and configuration file
- Resolves: RHEL-71262
Include latest fixes in python3-ipatests package
- Resolves: RHEL-67190
CVE-2024-11029 ipa: Administrative user data leaked through systemd journal

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2025-01-16 13:49:29 +01:00
Florence Blanc-Renaud
8f97c76dba ipa-4.12.2-9
- Resolves: RHEL-70759
Fix typo in ipa-migrate log file i.e 'Privledges' to 'Privileges'
- Resolves: RHEL-70477
ipa-server-upgrade fails after established trust with ad
- Resolves: RHEL-70253
Upgrade to ipa-server-4.12.2-1.el9 OTP-based bind to LDAP without enforceldapotp is broken
- Resolves: RHEL-69926
add support for python cryptography 44.0.0
- Resolves: RHEL-69635
All user groups are not being included during HSM token validation

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2024-12-11 09:46:58 +01:00
Florence Blanc-Renaud
1e38d43370 ipa-4.12.2-8
- Resolves: RHEL-69300 Support GSSAPI in Cockpit on IPA servers
- Resolves: RHEL-68447 ipa trust-add fails in FIPS mode with an internal error has occurred
- Resolves: RHEL-57674 Use RSNv3 and enable cert pruning by default in RHEL 10.0

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2024-11-27 19:43:17 +01:00
Florence Blanc-Renaud
255a8322a5 ipa-4.12.2-7
- Resolves: RHEL-66599 vault-add fails in FIPS mode
- Resolves: RHEL-66598 ipa-migrate should also migrate DNS forward zones
- Resolves: RHEL-66597 ipa-migrate in stage mode fails with TypeError: 'NoneType' object is not iterable
- Resolves: RHEL-66595 Sentences truncated in man pages
- Resolves: RHEL-66592 IDP configuration in the IdM WebUI shows Organization is required
- Resolves: RHEL-65650 ipa-server-install with setup-dns fails 'job for ipa.service failed because the control process exited with error code'

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2024-11-12 09:00:18 +01:00
Florence Blanc-Renaud
b22e86ac9d ipa-4.12.2-6
- Resolves: RHEL-64018 Bump release for October 2024 mass rebuild

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2024-10-31 14:34:45 +01:00
Florence Blanc-Renaud
26cff073ee ipa-4.12.2-5
- Resolves: RHEL-61636 Uninstall ACME separately during PKI uninstallation

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2024-10-29 15:30:23 +01:00
Florence Blanc-Renaud
80f94e10a4 ipa-4.12.2-4
Bump version
Related: RHEL-59777 Rebase Samba to the latest 4.21.x release

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2024-10-21 18:05:17 +02:00
Florence Blanc-Renaud
66cc1eaeec ipa-4.12.2-4
- Related: RHEL-59777 Rebase Samba to the latest 4.21.x release
- Resolves: RHEL-59659 ipa dns-zone --allow-query '!198.18.2.0/24;any;' fails with Unrecognized IPAddress flags
- Resolves: RHEL-61636 Uninstall ACME separately during PKI uninstallation
- Resolves: RHEL-61723 Include latest fixes in python3-ipatests packages
- Resolves: RHEL-63325 Last expired OTP token would be considered as still assigned to the user

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2024-10-21 17:45:24 +02:00
Rafael Guterres Jeffman
c94e6ae745 ipa-4.12.2-3
Resolves: RHEL-33818 Remove python3-ipalib's dependency on python3-netifaces

Signed-off-by: Rafael Guterres Jeffman <rjeffman@redhat.com>
2024-09-24 10:22:22 -03:00
Florence Blanc-Renaud
5d90090676 ipa-4.12.2.2
- Resolves: RHEL-47294 SID generation task is failing when SELinux is in Enforcing mode
- Resolves: RHEL-56472 Include latest fixes in python3-ipatests packages
- Resolves: RHEL-56917 RFE add a tool to quickly detect and fix issues with IPA ID ranges
- Resolves: RHEL-56965 Backport test fixes in python3-ipatests
- Resolves: RHEL-58067 ipa replication installation fails in FIPS mode on rhel10
- Resolves: RHEL-59265 Default hbac rules are duplicated on remote server post ipa-migrate in prod-mode
- Resolves: RHEL-59266 Also enable SSSD's ssh service when enabling sss_ssh_knownhosts

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2024-09-18 11:23:26 +02:00
Florence Blanc-Renaud
0378d5e4e5 ipa-4.12.2.1
- Resolves: RHEL-54545 Covscan issues: Resource Leak
- Resolves: RHEL-54304 support for python cryptography 43.0.0
- Resolves: RHEL-49805 misleading warning for missing ipa-selinux-nfast package on luna hsm h/w
- Resolves: RHEL-46897 With unreachable AD, ipa trust returns an internal error

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2024-08-21 21:17:57 +02:00
Florence Blanc-Renaud
86420dd2f3 ipa-4.12.1-4
- Resolves: RHEL-53501 adtrustinstance only prints issues in check_inst() and does not log them
- Resolves: RHEL-52305 Unconditionally add MS-PAC to global config
- Resolves: RHEL-52223 ipa-replica/server-install with softhsm needs to check permission/ownership of /var/lib/softhsm/tokens to avoid install failure
- Resolves: RHEL-51937 Include latest fixes in python3-ipatests packages
- Resolves: RHEL-50805 ipa-migrate -Z with invalid cert options fails with 'ValueError: option error'
- Resolves: RHEL-49805 misleading warning for missing ipa-selinux-nfast package on luna hsm h/w
- Resolves: RHEL-49592 'Unable to log in as uid=admin-replica.testrealm.test,ou=people,o=ipaca' during replica install
- Resolves: RHEL-4879 RFE - Keep the configured value for the "nsslapd-ignore-time-skew" after a "force-sync"

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2024-08-08 17:24:14 +02:00
Florence Blanc-Renaud
6c2a5fa538 ipa-4.12.1-3
- Resolves: RHEL-49452 Include latest fixes in python3-ipatests packages
- Resolves: RHEL-49433 Adjust "ipa config-mod --addattr ipaconfigstring=EnforceLDAPOTP" to allow for non OTP users in some cases
- Resolves: RHEL-49432 ipa-migrate stage-mode is failing with error: Modifying a mapped attribute in a managed entry is not allowed
- Resolves: RHEL-49413 ipa-migrate with -Z option fails with ValueError: option error
- Resolves: RHEL-47157 ipa-migrate -V options fails to display version
- Resolves: RHEL-47148 Pagure #9629: Syntax error uninstalling the selinux-luna subpackage
- Resolves: RHEL-40892 ipa-server-install: token_password_file read in kra.install_check after calling hsm_validator in ca.install_check

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2024-07-18 13:25:00 +02:00
Florence Blanc-Renaud
fcc298685a ipa-4.12.1-2
- Resolves: RHEL-46607 kdc.crt certificate not getting automatically renewed by certmonger in IPA Hidden replica
- Resolves: RHEL-46606 ipa-client rpm post script creates always ssh_config.orig even if nothing needs to be changed
- Resolves: RHEL-46605 IPA Web UI not showing replication agreement for non-admin users
- Resolves: RHEL-46592 [RFE] Allow IPA SIDgen task to continue if it finds an entity that SID can't be assigned to
- Resolves: RHEL-46556 Include latest fixes in python3-ipatests packages
- Resolves: RHEL-42705 PSKC.xml issues with ipa_otptoken_import.py

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2024-07-08 19:27:27 +02:00
Troy Dawson
605fed4ed0 Bump release for June 2024 mass rebuild 2024-06-24 08:51:28 -07:00
Sudhir Menon
b1684f15a7 Include gating.yaml for c10s
Signed-off-by: Sudhir Menon <sumenon@redhat.com>
2024-06-13 18:35:13 +05:30
Julien Rische
38e4126e68 ipa-4.12.1-1
- CVE-2024-3183 freeipa: user can obtain a hash of the passwords of all domain users and perform offline brute force
  Resolves: RHEL-32233
- CVE-2024-2698 freeipa: delegation rules allow a proxy service to impersonate any user to access another target service
  Resolves: RHEL-40881

Signed-off-by: Julien Rische <jrische@redhat.com>
2024-06-12 17:57:09 +02:00
Florence Blanc-Renaud
881a120bf5 rpminspect: add automatic waiver for runpath check
The "runpath" check of rpminspect raises an error related
to DT_RPATH using /usr/lib64/samba for /usr/lib64/samba/pdb/ipasam.so.
This can be waived as ipasam.so is a plugin for smdb and
requires to have DT_RPATH set.
Add the path /usr/lib64/samba to the list of allowed DT_RPATH
to ignore the issue.

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2024-06-05 12:35:25 +02:00
Florence Blanc-Renaud
90dae868c3 ipa-4.12.0-1
- Resolves: RHEL-39144 Rebase ipa to the latest 4.12 version for RHEL 10
- Resolves: RHEL-30537 ipa: freeipa: argument injection into the username field of the /ipa/session/login_password requests
2024-06-04 19:55:30 +02:00
Troy Dawson
123abb92ab Bump release to rebuild on correct samba
Signed-off-by: Troy Dawson <tdawson@redhat.com>
2024-02-22 10:58:02 -08:00
Alexander Bokovoy
d41e5ca07b Support 389-ds with lmdb backend
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2024-02-08 18:24:08 +02:00
Alexander Bokovoy
f407801376 Detect samba private libraries
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2024-01-30 20:11:07 +02:00
Alexander Bokovoy
7365e8a23f More backports
remove CA affinity patch, not ready for backport yet.

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2024-01-30 18:09:49 +02:00
Alexander Bokovoy
f19c883a04 Rebuild against Samba 4.20rc1
Add upstream fixes
- Fix memory leak in Kerberos KDC driver
- Fix possible crash in IPA command line tool when accessing Kerberos credentials
- Compatibility fix for Python Cryptography 42.0.0
- Fix CA affinity when installing replica

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2024-01-30 17:40:53 +02:00
Fedora Release Engineering
dc24d637fb Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild 2024-01-24 12:01:16 +00:00
Fedora Release Engineering
9d0ac5b4ee Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild 2024-01-19 19:46:15 +00:00
Alexander Bokovoy
297837b973 FreeIPA security release for CVE-2023-5455
Release notes:
https://www.freeipa.org/release-notes/4-11-1.html

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2024-01-10 14:23:42 +02:00
Alexander Bokovoy
cbef046169 Backport various fixes found by RHEL and upstream tests
- timezone shift in handling certificates (due to py3.12 adaptation)
- 'reason' vs 'Reason' in PKI revocation JSON API response
- allow removal of minlength attribute from a custom password policy

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2023-11-08 11:50:46 +02:00
Alexander Bokovoy
eb660edcd1 Adopt to Samba changes in malformed SID processing
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2023-10-23 18:16:23 +03:00
Alexander Bokovoy
f81c02d7c7 FreeIPA 4.11.0 release
Update Fedora part of the spec file as we don't support building 4.11+
for versions below Fedora 39.

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2023-10-03 16:11:28 +03:00
Alexander Bokovoy
f3e42960a7 Depend on selinux-policy-38.28-1
- Depend on selinux-policy-38.28-1.fc39
- Add SELinux policy for passkey_child to be used without ipa-otpd
- Related: rhbz#2238474

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2023-09-18 15:31:55 +03:00
Alexander Bokovoy
2aa5a94633 Restore SELinux context during IPA client uninstallation
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2023-09-12 20:07:54 +03:00
Alexander Bokovoy
f52df9fbd5 Configure SSSD to access USB devices when enrolling IPA client
Resolves: rhbz#2238474

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2023-09-12 08:47:02 +03:00
Alexander Bokovoy
f4aadac5c3 Update to FreeIPA 4.11.0-beta1
Sync spec file to the upstream's template
2023-08-21 18:56:10 +03:00
Fedora Release Engineering
685d576312 Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2023-07-19 20:13:36 +00:00
Miro Hrončok
4ca56b848a Use ssl.match_hostname from urllib3 as it was removed from Python 3.12 2023-07-05 08:53:26 +02:00
Python Maint
bdbff27a6d Rebuilt for Python 3.12 2023-06-27 12:03:21 +02:00
Alexander Bokovoy
e2e40e4ca3 Upstream release 4.10.2
Synchronize patches with CentOS 9 Stream

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2023-06-13 14:46:27 +03:00
Alexander Bokovoy
4d4375dd2d Support python-cryptography 40.0
Use upstream fixes from https://pagure.io/freeipa/issue/9355

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2023-05-15 15:01:10 +03:00
Jerry James
c9357e5423 Change fontawesome-fonts R to match fontawesome 4.x 2023-03-30 10:40:45 -06:00
Rafael Guterres Jeffman
2c8ae7cea5 Migrated to SPDX license.
Signed-off-by: Rafael Guterres Jeffman <rjeffman@redhat.com>
2023-02-28 22:33:24 -03:00
Yaakov Selkowitz
61685c38bd Update RHEL requirement versions 2023-02-01 10:32:13 -05:00
Alexander Bokovoy
796470e053 Rebuild against samba 4.18.0RC1
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2023-01-20 15:14:23 +02:00
Fedora Release Engineering
8ab874381a Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2023-01-19 03:52:45 +00:00
Alexander Bokovoy
9ab0396eec Rebuild against krb5 1.20.1
ABI change brings KDB version 9.0

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2022-12-01 17:42:46 +02:00